commvault
14 known vulnerabilities affecting commvault products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-13738 | Medium | 0.6% | 9.8 | CommServe contained an authorization bypass vulnerability affecting a limited se… | |
| CVE-2026-13737 | Medium | 0.5% | 9.8 | CommServe contained an allowlist bypass vulnerability affecting command executio… | |
| CVE-2026-13739 | Medium | 0.4% | 9.8 | A legacy endpoint in Command Center contained an unauthenticated server-side req… | |
| CVE-2026-77104 | Medium | 0.4% | 7.5 | CommServe contained a path traversal issue affecting information disclosure. Sof… | |
| CVE-2026-77089 | Medium | 0.3% | 9.8 | Command Center API contained an authentication bypass issue affecting privilege … | |
| CVE-2026-77106 | Medium | 0.3% | 8.8 | Cvlaunchd contained a missing authorization issue affecting command execution au… | |
| CVE-2026-77103 | Medium | 0.3% | 7.5 | CommServe contained an authentication bypass issue affecting access authorizatio… | |
| CVE-2026-77101 | Medium | 0.3% | 7.5 | CommServe contained a stack-based buffer overflow issue affecting service availa… | |
| CVE-2026-77102 | Medium | 0.3% | 7.5 | CommServe contained a heap-based buffer overflow issue affecting service availab… | |
| CVE-2026-77098 | Medium | 0.3% | 9.8 | Private Metrics Server contained an SQL injection condition affecting database o… | |
| CVE-2026-77097 | Medium | 0.3% | 8.2 | Private Metrics Server contained a missing authentication condition affecting me… | |
| CVE-2026-77092 | Medium | 0.2% | 9.8 | Content Extractor contained a deserialization of untrusted data issue affecting … | |
| CVE-2026-77105 | Medium | 0.2% | 8.8 | CommServe contained a cryptographic signature verification issue affecting privi… | |
| CVE-2026-77091 | Medium | 0.1% | 7.8 | DataCube contained a path traversal issue affecting security feature enforcement… |